Ransomware Group intelligence
Metaencryptor
ActiveTrack Metaencryptor with 45 published victims and 2 known leak locations in a single intelligence view.
Overview
Metaencryptor is tracked by Breach House as a ransomware group with 45 published victims.
United States is currently the most targeted country in this dataset.
2 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (2)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 2 | Onion service | Up checked 1h ago | metacrpttdfpbm4qoxzcrqqgr6e6zafpazgxm72knmujw2mwvi34rwad.onion |
| Leak location 1 | Onion service | Up checked 1h ago | metacrptmytukkj7ajwjovdpjqzd7esg5v3sg344uzhigagpezcqlpyd.onion |
Top Activity Sectors (13)
Typical Attacks (10)
▼MITRE ATT&CK does not currently catalogue Metaencryptor, so this is our assessment of the techniques it uses, drawn from public reporting. The techniques themselves, and every "what that means" definition below, come from MITRE ATT&CK v19.2. Confidence: medium. Treat it as orientation, not attribution.
-
T1059.001 PowerShell Execution
What they do: metaencryptor uses PowerShell scripts to execute payload deployment and system modifications on compromised hosts.
What that means: Adversaries may abuse PowerShell commands and scripts for execution.
-
T1106 Native API Execution
What they do: metaencryptor leverages native API calls to interact with Windows services and evade behavioral detection.
What that means: Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
-
What they do: metaencryptor modifies Windows Registry Run Keys to ensure malware persistence across reboots.
What that means: Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
-
T1685 Disable or Modify Tools Defense Impairment
What they do: metaencryptor disables antivirus tools and security software using registry modifications and service termination commands.
What that means: Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities.
-
T1027.016 Junk Code Insertion Stealth
What they do: metaencryptor inserts junk code into legitimate binaries to evade static analysis and detection.
What that means: Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
-
T1070.004 File Deletion Stealth
What they do: metaencryptor deletes Volume Shadow Copies and backup directories via command-line utilities to prevent recovery.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1021.002 SMB/Windows Admin Shares Lateral Movement
What they do: metaencryptor moves laterally through SMB/Windows Admin Shares to access additional networked systems.
What that means: Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
-
T1560.001 Archive via Utility Collection
What they do: metaencryptor archives stolen data using utility tools prior to exfiltration for extortion leverage.
What that means: Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
-
T1486 Data Encrypted for Impact Impact
What they do: metaencryptor encrypts victim files using symmetric encryption algorithms targeting critical business data.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: metaencryptor calls system shutdown commands to inhibit recovery processes and maximize disruption.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Victims (45)
Search, filter and paginate the victim timeline for Metaencryptor. Showing 1–45 of 45.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Woodlore International Inc. id32028 View details | Canada | Services | ||
|
Woodlore.ca operates within the Services sector and is located in Canada. The entity represents a business organization documented within a threat-intelligence index under the classification ransomware victim. Its inclusion links the organization to metaencryptor, a threat actor identified in relation to ransomware activity within this catalog context. This description maintains neutrality regarding specific incident details, avoiding assumptions about data accessed, operational impact, or confirmed breach specifics. The listing serves to contextualize Woodlore.ca as an affected entity tied to a recognized cyber threat actor for analytical and defensive reference purposes. |
|||||
| Ransomware | Woodlore International Inc. id32028 View details | Canada | Services | ||
|
Woodlore is manufacturer specializes in laminate casegood production for furniture. Revenue $ 30 M |
|||||
| Ransomware | Trailer Transit Inc id32029 View details | United States | Transportation / Travel / Logistics | ||
|
www.trailertransit.com operates within the United States transportation, travel, and logistics sector, providing services aligned with freight movement, passenger transit coordination, and supply-chain connectivity. The entity is cataloged as a ransomware victim within this threat-intelligence index, linked to the metaencryptor threat actor. This listing reflects the cybersecurity profile of the organization in relation to a ransomware-related incident and does not confirm stolen data, ransom activity, or specific technical compromise details. The record serves to inform threat analysts and security professionals about affected entities in critical infrastructure sectors. It remains a neutral reference point for monitoring ransomware exposure across transportation and logistics environments. |
|||||
| Ransomware | Trailer Transit Inc id32029 View details | United States | Transportation / Travel / Logistics | ||
|
Nationwide power-only transport services with 40+ years of experience. Trust Trailer Transit for dependable and accurate trailer transport solutions. Revenue: $22 M |
|||||
| Ransomware | Weber Water Resources id32030 View details | United States | Services | ||
|
www.weberwaterresources.com operates within the Services sector and is located in the United States. The entity is cataloged as a ransomware victim linked to the metaencryptor threat actor in this threat-intelligence index. This listing type indicates documented exposure to ransomware activity associated with metaencryptor, providing context for security teams assessing risks within the Services sector. The description maintains neutrality regarding incident specifics, focusing on verified listing attributes rather than unconfirmed claims about data stolen, ransom demands, or operational impact. Such entries support threat-intel workflows by mapping victim profiles to actor attribution for defensive analysis and sector-wide risk awareness. |
|||||
| Ransomware | Weber Water Resources id32030 View details | United States | Services | ||
|
Founded in 1910, Weber Water Resources has been providing the widest range of water resource solutions at the lowest available risk to clients for over a century. Through our superior problem solving ability, Weber Water Resources partners with public and private clients to achieve the most equitable outcome possible on each project. revenue $25 M |
|||||
| Ransomware | MPA Pharma GmbH id32031 View details | Germany | Healthcare / Pharma | ||
|
mpapharma.com operates within the healthcare and pharmaceutical sector, based in Germany. The entity represents a healthcare organization whose infrastructure was identified within threat-intelligence indexing as a ransomware victim linked to the metaencryptor threat actor. This listing reflects cybersecurity intelligence analysis concerning compromised systems or organizational exposure within the medical and pharmaceutical domain. The description remains neutral regarding specific incident details, as confirmed specifics such as data stolen or ransom demands are not publicly verified for this entity. It is cataloged to inform stakeholders about ransomware exposure patterns affecting critical healthcare and pharma sectors in Germany. |
|||||
| Ransomware | MPA Pharma GmbH id32031 View details | Germany | Healthcare / Pharma | ||
|
MPA Pharma GmbH is an internationally active, rapidly growing company specializing in the import and trade of high-quality pharmaceuticals, including both patented and generic products. With over 35 years of expertise in the pharmaceutical market, they also provide contract manufacturing services for third parties. Their primary clients include pharmacies and businesses in need of reliable pharmaceutical and medical products. Revenue $614 Million |
|||||
| Ransomware | Aquamar Inc id32032 View details | United States | Agriculture / Food | ||
|
aquamarseafood.com operates within the Agriculture and Food sector, serving the United States market with seafood-related products or services. As a ransomware victim listed in our threat-intelligence index, it is associated with the threat actor metaencryptor. This designation reflects the cybersecurity event documented in the index without disclosing unverified details such as data stolen, ransom demands, or precise breach timelines. The listing type identifies aquamarseafood.com specifically within ransomware victim records linked to metaencryptor, providing context for analysts tracking cyber threats against critical food and agricultural infrastructure. All information presented remains neutral and adheres to factual constraints regarding incident specifics. |
|||||
| Ransomware | Aquamar Inc id32032 View details | United States | Agriculture / Food | ||
|
Aquamar, Inc. specializes in providing high-quality, wild-caught seafood products that are both delicious and nutritious. The company targets markets in the U.S., Canada, and Latin America, focusing on retail and foodservice sectors. |
|||||
| Ransomware | Corona Corporation id32033 View details | Japan | Retail / E-commerce | ||
|
corona.co.jp operates within Japan's retail and e-commerce sector, providing digital commerce and retail services to customers and partners. The entity is documented in the threat-intelligence index under the listing type ransomware victim, associated with the metaencryptor threat actor or source. This classification reflects observed threat activity targeting retail and e-commerce infrastructure in the Japanese market. The entry serves as a reference point for cybersecurity professionals assessing ransomware exposure across regional commerce sectors. It was listed as a ransomware victim associated with metaencryptor. |
|||||
| Ransomware | Corona Corporation id32033 View details | Japan | Retail / E-commerce | ||
|
The company specializes in creating a comfortable home environment, focusing on heating, cooling and hot water technologies. It was founded at April 1937, and now have more than 2000 employee. Corona Corporation is stock listed, ticker 5909.T at Tokyo Stock Exchange (Standard) |
|||||
| Ransomware | FactoryFive id32034 View details | United States | IT | ||
|
factoryfive.com operates within the IT sector and is situated in the United States. The entity is cataloged in this threat-intelligence index under the listing type ransomware victim, with metaencryptor identified as the associated threat actor or source. This designation reflects the intelligence assessment linking the organization to this specific cyber threat activity within the ransomware threat landscape. The description remains neutral and avoids speculation regarding breach details, data handling, or operational impact. It serves to document the verified relationship between factoryfive.com, the metaencryptor actor, and the ransomware victim classification for catalog and research purposes. |
|||||
| Ransomware | FactoryFive id32034 View details | United States | IT | ||
|
Factory Five Racing Inc — kit-car manufacturer (Cobra replicas, GTM, Type 65 Coupe, 33 Hot Rod). 9 Tow Road, Wareham MA 02571-1086. ~90 employees, 158 endpoints. Revenue $5.5-6.5M/yr (credit card processing ~$4.3M, avg ticket $1245). Exfiltrated data categories (~130GB): correspondence (PST archives), CRM contacts (GoldMine), ERP/pricing, engineering CAD (SolidWorks/Rhino), banking statements, insurance policies, tax documentation, legal contracts/NDAs, database backups. Includes detailed materials on several ongoing lawsuits — parties, witnesses, testimonies, and related case files, alongside private correspondence. Risk zones: PCI DSS (card processing $4.3M/yr), MA 201 CMR 17.00 (Massachusetts personal data protection), GDPR (EU clients), CCPA (California clients), active IRS audit, active MA Sales Tax audit, FTC Safeguards Rule. Reputational: customer warranties, partner contracts (SEMA supplier), licenses, litigation exposure. CEO: David T. Smith. |
|||||
| Ransomware | The Lowell Hotel New York id20804 View details | United States | Hospitality / Food & Beverage / Tourism | ||
|
The Lowell is a New York legacy and a landmark luxury hotel, located near Central Park and all the wonderful shops of Madison Avenue. Established in 1927. |
|||||
| Ransomware | Groupe Devimco id20448 View details | Canada | Construction / Real Estate | ||
|
As a leader in real estate development in Quebec, Groupe Devimco has been designing and creating unique and mixed-use living environments for 30 years. Revenue 2024 : $ 44 M |
|||||
| Ransomware | Third Avenue Management id19043 View details | United States | Services | ||
|
Third Avenue Management is a New York City-based asset manager that utilizes a disciplined, value-oriented, and asset-based approach to investing in publicly traded securities. Revenue $48 M |
|||||
| Ransomware | Lee Hartman & Sons id16945 View details | United States | Communication / Marketing | ||
|
Lee Hartman & Sons, Inc., provides design, engineering, installation, service and rental services of audiovisual, presentation, videoconferencing, video-streaming, digital signage, video-production, and broadcast solutions in the Mid Atlantic Region of United States. The company was established in 1936. Revenue $18.5 Million |
|||||
| Ransomware | Saeilo id13957 View details | Germany | Manufacturing / Engineering | ||
|
Saeilo is a diversified manufacturing company consisting of three operating divisions. SMI is a national network specializing in contract precision metalworking and other manufacturing services. Kahr Arms designs and manufactures quality firearms, primarily for personal protection and law enforcement back-up and off-duty carry. Revenue $44 M |
|||||
| Ransomware | Life University id13955 View details | United States | Education | ||
|
Life University is a private university Leading Chiropractic and Holistic Health University located in Marietta, Georgia, USA. |
|||||
| Ransomware | MBS Radio id13840 View details | Canada | Communication / Marketing | ||
|
MBS Radio is a locally owned and operated group of 24 radio stations across Nova Scotia, New Brunswick and Prince Edward Island. |
|||||
| Ransomware | Carlex Glass Luxembourg S.A. id13636 View details | Luxembourg | Communication / Marketing | ||
|
Carlex Glass Luxembourg SA in Grevenmacher is a part of Webasto, the world leader in roof systems and convertible roofs as well as parking heaters. Carlex produces glass elements for passenger cars, counts many international car manufacturers among its customers and was formerly part of Carlex Glass America, LLC, headquartered in Nashville, Tennessee (USA). |
|||||
| Ransomware | MBE CPA id13019 View details | United States | Services | ||
|
MBE CPA is accounting service and business services company, provide financial solutions for individual and business. Revenue: $25 M |
|||||
| Ransomware | Autohaus Ebert id12371 View details | Germany | Telecommunications | ||
|
Autohaus Ebert GmbH & Co.KG has been there for its customers for more than 120 years. At 12 locations around the Weinheim headquarters, the company offers a wide range of new and used cars as well as commercial vehicles. In addition, Autohaus Ebert GmbH & Co.KG offers comprehensive services related to automobiles. Revenue: $200M |
|||||
| Ransomware | Elbers GmbH & Co. KG id12370 View details | Germany | Retail / E-commerce | ||
|
Wholesale and retail trade, import and export of flowers, plants, vegetables and horticultural necessities. Revenue: $ 3 M |
|||||
| Ransomware | Jetson Specialty Marketing Services, Inc. id12369 View details | United States | Communication / Marketing | ||
|
JSM is a full-service direct marketing communications company steadfast in assisting clients acquire new customers and build profitable, long-term relationships with those customers. From Analytics and Database Management to Direct Mail, Critical Communications, Digital Variable Print Production to Postal Optimization, Piece-level Tracking and Response Processing, JSM has a suite of solutions to assist in growing client's business. |
|||||
| Ransomware | Vega Reederei GmbH & Co. KG id12368 View details | Germany | Transportation / Travel / Logistics | ||
|
Headquartered at the Port of Hamburg, Vega is one of the world's fastest-growing shipping companies. Vega offers its customers a wide range of services that include shipbuilding, shipping operations, chartering, ship disposal and financial services. Read less Revenue: EUR 19M Year 2022 |
|||||
| Ransomware | Max Wild GmbH id12367 View details | Germany | Services | ||
|
Max Wild GmbH, based in Berkheim, has been responsible for the professional and sustainable implementation of numerous services in the field of construction, demolition, environment & recycling and logistics since 1955. As a family business, Max Wild offers its customers consistency and conversion strength combined with great regional connectivity. Customers receive innovative and tailor-made solutions for small and large projects and are supported with an individual service package from all divisions. |
|||||
| Ransomware | stormtech id9893 View details | IT | |||
|
stormtech |
|||||
| Ransomware | Garda id9892 View details | Other | |||
|
Garda |
|||||
| Ransomware | JD Sprinter Holdings 2010 SL id9737 View details | Communication / Marketing | |||
|
JD Sprinter Holdings 2010 SL retails sportswear, outdoor clothing, and related equipment. over 7500 employees 109 M EUR EBITDA |
|||||
| Ransomware | TANATEX Chemicals id9319 View details | Manufacturing / Engineering | |||
|
TANATEX Chemicals is an international organisation that sells, develops, and produces chemicals for the textile industry. The company have been leading innovative solutions for textile processing for almost 60 years. It has worldwide network of offices and distributors, support customers all over the world.Revenue: $117M Year 2022 |
|||||
| Ransomware | Belzona UK Ltd id8901 View details | United Kingdom | Manufacturing / Engineering | ||
|
Specialising in erosion, corrosion and chemical protection, Belzona is a world leader in the design and manufacture of repair composite materials and protective coatings for machinery, equipment, buildings and structures. |
|||||
| Ransomware | Dillon Supply id8167 View details | Manufacturing / Engineering | |||
|
Established in 1914, Dillon Supply distributes industrial products. They are heaquartered in Raleigh, North Carolina. Parent company Descours & Cabaud. D&C is a 200-year old company that is the European leader in MRO, Industrial and Construction Supply with over 650 locations worldwide. Sales: $313,865,000 Year 2021 |
|||||
| Ransomware | Epicure id8166 View details | Healthcare / Pharma | |||
|
Epicure is a online shop with healthy eating. The company is primarily focused on educating the community on healthy eating. Revenue: $117 M Year 2021 |
|||||
| Ransomware | Coswell id8165 View details | Healthcare / Pharma | |||
|
The Company Coswell is an italian family run group of companies specialized in manufacturing and distribution of body and oral care products, health foods, masstige and selective fragrances, skin care and cosmetics in the mass market, perfumeries and pharmacies. Revenue: $157M Year 2021 |
|||||
| Ransomware | BOB Automotive Group id8164 View details | Manufacturing / Engineering | |||
|
Die BOB Automotive Group mit Hauptsitz in Essen ist eine Holding für renommierte und starke Automobilunternehmen in Nordrhein-Westfalen. Derzeit ist die BOB-Gruppe mit 20 Autohäusern im Ruhrgebiet, im Rheinland und im Bergischen Land vertreten. 21. Standort ist die Verwaltung, in der die gesamten Querschnittsfunktionen wie zum Beispiel das Personalwesen, Buchhaltung und Controlling, die IT, die Fahrzeugdisposition oder das Marketing gebündelt sind und die administrative Unterstützung für die operativen Standorte leisten. Revenue: 240 M EUR Year 2022 |
|||||
| Ransomware | Seoul Semiconductor id8163 View details | Manufacturing / Engineering | |||
|
Seoul Semiconductor is the top LED manufacturing company in Korea and No. 3 in the world. Over the past 30 years, Seoul has devoted itself to R&D with a vast patent portfolio and is leading second generation LED technology. Stock: Korea Exchange. Revenue: $842 M Year 2022 |
|||||
| Ransomware | Kraiburg Austria GmbH id8162 View details | Austria | Communication / Marketing | ||
|
Kraiburg Austria GmbH Lösungen für die Reifenrunderneuerung. Bei KRAIBURG Retreading Materials vereinen wir über 70 Jahre Erfahrung im Umgang mit Compounding mit einer qualitätsorientierten Unternehmenspolitik – unsere Basis für beste Produkte und zufriedene Kunden.Revenue: $76M Year 2021 |
|||||
| Ransomware | Autohaus Ebert GmbH id8161 View details | Germany | Telecommunications | ||
|
Autohaus Ebert GmbH & Co.KG has been there for its customers for more than 120 years. At 12 locations around the Weinheim headquarters, the company offers a wide range of new and used cars as well as commercial vehicles. In addition, Autohaus Ebert GmbH & Co.KG offers comprehensive services related to automobiles. Revenue: $200M |
|||||
| Ransomware | CVO Antwerpen id8160 View details | Belgium | Education | ||
|
Education for adults.Revenue: $72M |
|||||
| Ransomware | ICON Creative Studio id8159 View details | Canada | Communication / Marketing | ||
|
ICON Creative Studio is Canada’s largest independently owned CG Animation Studio, located in the historic Gastown district of Vancouver, BC Canada, housing over 950 talented creatives ranging from design, storyboarding, modeling, rigging, animation, shot finaling, lighting, visual effects and compositing artists alongside creative and management teams.Revenue: $410M |
|||||
| Ransomware | Heilmann Gruppe id8158 View details | Germany | Transportation / Travel / Logistics | ||
|
Heilmann Gruppe. The purchase and sale of potatoes and onions, as well as all related activities not subject to authorisation. The following companies belong to Heilmann Gruppe: Heilmann AG, Agricola, Heilmann Logistics. Revenue: $134M Year 2021 |
|||||
| Ransomware | Schwälbchen Molkerei AG id8157 View details | Germany | Communication / Marketing | ||
|
Schwälbchen Molkerei AG is a company that operates in the Consumer Services industry. It is a German manufacturer and wholesaler of dairy products. It operates in two business segments: milk production and merchandise. The Company's range of products includes fresh milk, homogenized milk, cream and yogurt, butter, cheese manufactures as well as curd, among others. The company is headquartered in Bad Schwalbach, Hessen, Germany. Revenue: $211M Year 2022 |
|||||
| Ransomware | Münchner Verlagsgruppe GmbH id8156 View details | Germany | Other | ||
|
Münchner Verlagsgruppe GmbH is a company that operates in the Publishing industry. It has $36M of revenue. The company is headquartered in Munich, Bavaria, Germany. |
|||||